What are the next steps for boards to strengthen cyber governance?
Businesses shouldn't wait for the finalised Cyber Governance Code of Practice to prioritise cyber resilience. Taking a proactive approach to assessing cyber risks can help you prepare for the potential impact of a cyber-attack that could affect the organisation, its partners and its customers.
To help them implement the recommendations of the Cyber Governance Code of Practice, organisations and boards should take the following actions now.
1 Establish board-level oversight
Assign a board-level executive to sponsor and oversee the cyber security strategy and measures undertaken by the organisation. Ensure cyber risks and incident response measures are included on the agenda for every board meeting, audit committee and other relevant forums.
2 Conduct regular risk assessments
Prioritise your resources and efforts to mitigate key cyber security risks by adopting a risk-based approach. Conducting regular risk assessments enables the identification of potential threats, and implementation of controls based on the identified risks, which can better protect critical assets and data from cyber threats.
3 Build a culture of cyber security through regular staff training
Providing regular training to employees and contractors on cyber security good practices to help strengthen your security posture. Increase awareness of several cyber threats, promote good security practices, and provide members of staff with the necessary knowledge and skills to identify and respond to cyber incidents. Additionally, set up tailored training on cyber security for the board and other critical stakeholders to increase their awareness of potential risks facing the organisation.
4 Maximise cyber security with external expertise
Those without internal cyber security expertise can seek support from external cyber security experts to provide insights and guidance on implementing effective cyber security measures that align with the organisation's risk profile. Additionally, you should determine how to obtain independent assurance over your organisation's cyber security controls.
The Cyber Governance Code of Practice is just one tool to help you manage your cyber risks, with many large and listed companies choosing NIST, CIS or similar frameworks, which provide additional technical cyber security controls beyond the Code. While awaiting the final Code, boards need to take the lead in prioritising cyber resilience. By adopting these principles and ensuring robust cyber security measures, you can minimise the impact of cyber-attacks, safeguard your reputation and ensure business continuity.
For more insight, guidance and to support your technology teams in establishing ongoing assurance over your cyber security controls get in touch with Avik Chandra.
